2026 European Commission — AWS / Europa web hosting (CERT-EU: TeamPCP/Trivy chain; ~29+ Union entities; ShinyHunters leak)
Data compromised
Names, emails, email content, and web-platform material from Europa-hosted assets; multi-entity Union exposure per CERT-EU
Technical writeup
In late March 2026, the European Commission confirmed a security incident involving compromise of an Amazon Web Services (AWS) account used for the Europa.eu web hosting ecosystem—distinct from a failure of AWS core infrastructure. Subsequent reporting and CERT-EU analysis attributed activity to the TeamPCP threat group, describing use of a compromised AWS API key with management rights over other Commission AWS accounts—linked in press to the broader Trivy supply-chain / credential-stealer campaign—with initial intrusion activity summarized around March 10, 2026. CERT-EU stated the breach potentially affected websites hosted for up to 71 clients of the Europa web hosting service (42 internal Commission clients and at least 29 other Union entities). Attackers reportedly used tools such as TruffleHog to hunt for additional secrets and created new access keys to evade detection before data theft. The extortion group ShinyHunters published a dataset (e.g., ~90 GB compressed / ~340 GB uncompressed cited in trade reporting) containing names, emails, and substantial outbound email content; tens of thousands of files with personal information were confirmed in CERT-EU’s analysis. Core internal Commission IT systems were not reported as affected in the same way as the web-hosting footprint; AWS emphasized customer account control issues rather than AWS product defects.
Root cause
AWS account compromise; TeamPCP attribution per CERT-EU; Trivy supply-chain–linked credential theft cited in press; ShinyHunters publication
References
- https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain
- https://www.bleepingcomputer.com/news/security/cert-eu-european-commission-hack-exposes-data-of-30-eu-entities/
- https://www.securityweek.com/european-commission-reports-cyber-intrusion-and-data-theft/
- https://www.bleepingcomputer.com/news/security/european-commission-investigating-breach-after-amazon-cloud-hack/
- https://techcrunch.com/2026/03/27/european-commission-confirms-cyberattack-after-hackers-claim-data-breach/
- https://www.networkworld.com/article/4151383/european-commission-data-stolen-in-a-cyberattack-on-the-infrastructure-hosting-its-web-sites-2.html
- https://www.engadget.com/cybersecurity/european-commission-confirms-data-breach-200000982.html
- https://www.csoonline.com/article/4151363/european-commission-data-stolen-in-a-cyberattack-on-the-infrastructure-hosting-its-web-sites.html
- https://www.theregister.com/2026/03/30/european_commission_breach/